Vulnerability index

Browse CVEs

7,366 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Cross-Site Request Forgery (CSRF)CWE-352 × clear
Unclassified HIGH 7.1
CVE-2025-48304

Cross-Site Request Forgery (CSRF) vulnerability in Gary Illyes Google XML News Sitemap plugin gn-xml-sitemap allows Stored XSS.This issue affects Goo…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified HIGH 7.1
CVE-2025-48306

Cross-Site Request Forgery (CSRF) vulnerability in developers savyour Savyour Affiliate Partner savyour-affiliate-partner allows Stored XSS.This issu…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified HIGH 8.8
CVE-2025-7812

The Video Share VOD – Turnkey Video Site Builder Script plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and i…

Mitigation only
Fix from $1,950 2025-08-28
Unclassified HIGH 7.1
CVE-2025-58217

Cross-Site Request Forgery (CSRF) vulnerability in GeroNikolov Instant Breaking News instant-breaking-news allows Stored XSS.This issue affects Insta…

Mitigation only
Fix from $1,950 2025-08-27
Bevy MEDIUM 6.5
CVE-2025-54598

The Bevy Event service through 2025-07-22, as used for eBay Seller Events and other activities, allows CSRF to delete all notifications via the /noti…

Fix: after 2025-06-24
Fix from $1,600 2025-08-27
Unclassified HIGH 8.1
CVE-2025-8592

The Inspiro theme for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.1.2. This is due to missing or in…

Mitigation only
Fix from $1,950 2025-08-21
Open Shop HIGH 8.8
CVE-2025-50902

Cross Site Request Forgery (CSRF) vulnerability in old-peanut Open-Shop (aka old-peanut/wechat_applet__open_source) thru 1.0.0 allows attackers to ga…

Fix: after 1.0.0
Fix from $1,950 2025-08-20
Digital Experience Platform MEDIUM 6.8
CVE-2025-43748

Insufficient CSRF protection for omni-administrator users in Liferay Portal 7.0.0 through 7.4.3.119, and Liferay DXP 2024.Q1.1 through 2024.Q1.6, 202…

Fix: 7.4.3.120 / 2024.Q1.7+
Fix from $1,600 2025-08-20
Unclassified MEDIUM 5.4
CVE-2025-8102

The Easy Digital Downloads plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.5.0. This is due …

Mitigation only
Fix from $1,600 2025-08-20
Unclassified HIGH 7.5
CVE-2025-54052

Cross-Site Request Forgery (CSRF) vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna-wpl allows PHP Local File Inclus…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified MEDIUM 5.3
CVE-2025-49896

Cross-Site Request Forgery (CSRF) vulnerability in wptasker WP Discord Post Plus – Supports Unlimited Channels allows Cross Site Request Forgery. Th…

Mitigation only
Fix from $1,600 2025-08-20
Unclassified HIGH 8.8
CVE-2025-49399

Cross-Site Request Forgery (CSRF) vulnerability in Basix NEX-Forms nex-forms-express-wp-form-builder allows Cross Site Request Forgery.This issue aff…

Mitigation only
Fix from $1,950 2025-08-20
Unclassified CRITICAL 9.6
CVE-2025-49381

Cross-Site Request Forgery (CSRF) vulnerability in ads.txt Guru ads.txt Guru Connect adstxt-guru-connect allows Cross Site Request Forgery.This issue…

Mitigation only
Fix from $2,300 2025-08-20
Unclassified HIGH 8.8
CVE-2025-49382

Cross-Site Request Forgery (CSRF) vulnerability in DexignZone JobZilla - Job Board WordPress Theme jobzilla allows Privilege Escalation.This issue af…

Mitigation only
Fix from $1,950 2025-08-20
Digital Experience Platform MEDIUM 6.5
CVE-2025-43745

A CSRF vulnerability in Liferay Portal 7.4.0 through 7.4.3.132, and Liferay DXP 2025.Q2.0 through 2025.Q2.7, 2025.Q1.0 through 2025.Q1.14, 2024.Q4.0 …

Fix: 2024.q1.20 / 2025.Q1.16+
Fix from $1,600 2025-08-19
Unclassified MEDIUM 6.1
CVE-2025-7684

The Last.fm Recent Album Artwork plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.2. This i…

Mitigation only
Fix from $1,600 2025-08-16
Unclassified MEDIUM 6.1
CVE-2025-7686

The weichuncai(WP伪春菜) plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5. This is due to m…

Mitigation only
Fix from $1,600 2025-08-16
Unclassified MEDIUM 6.1
CVE-2025-7683

The LatestCheckins plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1. This is due to missing o…

Mitigation only
Fix from $1,600 2025-08-16
Unclassified MEDIUM 6.1
CVE-2025-7668

The Linux Promotional Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4. This is due …

Mitigation only
Fix from $1,600 2025-08-16
Unclassified MEDIUM 6.5
CVE-2025-49895

Cross-Site Request Forgery (CSRF) vulnerability in iThemes ServerBuddy by PluginBuddy.Com allows Object Injection.This issue affects ServerBuddy by P…

Mitigation only
Fix from $1,600 2025-08-16
Unclassified MEDIUM 6.1
CVE-2025-7688

The Add User Meta plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0.1. This is due to missin…

Mitigation only
Fix from $1,600 2025-08-15
Mblog MEDIUM 6.5
CVE-2025-8992

A vulnerability has been found in mtons mblog up to 3.5.0. Affected by this issue is some unknown functionality. The manipulation leads to cross-site…

Fix: after 3.5.0
Fix from $1,600 2025-08-15
Unclassified HIGH 8.8
CVE-2025-53587

Cross-Site Request Forgery (CSRF) vulnerability in ApusTheme Findgo findgo allows Cross Site Request Forgery.This issue affects Findgo: from n/a thro…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified MEDIUM 6.5
CVE-2025-53249

Cross-Site Request Forgery (CSRF) vulnerability in hakeemnala Build App Online build-app-online allows Cross Site Request Forgery.This issue affects …

Mitigation only
Fix from $1,600 2025-08-14
Unclassified HIGH 8.2
CVE-2025-52797

Cross-Site Request Forgery (CSRF) vulnerability in josepsitjar StoryMap wp-storymap allows SQL Injection.This issue affects StoryMap: from n/a throug…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified MEDIUM 5.4
CVE-2025-53219

Cross-Site Request Forgery (CSRF) vulnerability in pl4g4 WP-Database-Optimizer-Tools wp-database-optimizer-tools allows Cross Site Request Forgery.Th…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified HIGH 7.1
CVE-2025-52765

Cross-Site Request Forgery (CSRF) vulnerability in lisensee NetInsight Analytics Implementation Plugin netinsight-analytics-implementation-plugin all…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified HIGH 8.8
CVE-2024-53946

The KuWFi 4G LTE AC900 router 1.0.13 is vulnerable to Cross-Site Request Forgery (CSRF) on its web management interface. This vulnerability allows an…

Mitigation only
Fix from $1,950 2025-08-14
Unclassified MEDIUM 5.4
CVE-2025-54682

Cross-Site Request Forgery (CSRF) vulnerability in CRM Perks Connector for Gravity Forms and Google Sheets wp-gravity-forms-spreadsheets allows Cross…

Mitigation only
Fix from $1,600 2025-08-14
Unclassified MEDIUM 5.4
CVE-2025-54674

Cross-Site Request Forgery (CSRF) vulnerability in mklacroix Product Configurator for WooCommerce product-configurator-for-woocommerce allows Cross S…

Mitigation only
Fix from $1,600 2025-08-14